ST-2026-213 · Authentication & identity
AWS IAM Account Access Manager centralizes workforce IAM role assignments
AWS made IAM Account Access Manager generally available on 10 August 2026, giving administrators a centralized way to assign IAM roles in AWS accounts to workforce users and groups in IAM Identity Center while retaining IAM-role flexibility.
Previous state
Before Account Access Manager, customers could either federate users separately into each AWS account and define permissions through IAM roles in each account, or federate once through IAM Identity Center and manage access centrally with AWS managed permission sets.
Current state
IAM Account Access Manager lets administrators assign IAM roles in AWS accounts to workforce users and groups managed through IAM Identity Center, using the IAM console, SDKs, CloudFormation or CDK, while preserving the underlying IAM role model.
Affected users
Who needs to care
AWS administrators managing workforce access to IAM roles across accounts through IAM Identity Center.
Required response
What to do
Evaluate the new centralized assignment surface against existing Identity Center and IAM role governance, and verify role permissions and account scope before delegating access.
Evidence boundary
What the source does not prove
AWS proves general availability of IAM Account Access Manager, its workforce user/group assignment model and supported management surfaces. It does not make existing IAM roles automatically assigned, replace IAM permission review, or change the permissions contained in customer-managed roles.
Lifecycle history
Dated event sequence
- IAM Account Access Manager becomes generally available
AWS announced centralized assignment of IAM roles to Identity Center workforce users and groups.
Evidence ledger
First-party sources
- 01Amazon Web Services — AWS IAM Account Access Manager is now generally available
Official AWS What's New · 2026-08-10
Open official source ↗